CVE-2019-19722: Null Pointer Dereference
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19722?
CVE-2019-19722 is a vulnerability in Dovecot, a popular mail server, that allows an attacker to crash a push-notification driver with a crafted email.
How can an attacker exploit CVE-2019-19722?
An attacker can exploit CVE-2019-19722 by sending a crafted email with a group address as either the sender or the recipient, causing a NULL Pointer Dereference and crashing the push-notification driver.
What is the severity of CVE-2019-19722?
The severity of CVE-2019-19722 is medium, with a CVSSv3 score of 5.3.
Which software versions are affected by CVE-2019-19722?
Dovecot versions before 2.3.9.2 are affected by CVE-2019-19722. Fedora versions 30 and 31 are also affected.
How can CVE-2019-19722 be mitigated?
To mitigate CVE-2019-19722, users should update Dovecot to version 2.3.9.2 or later.